Remote Attack Vulnerability in IBM Concert Software
CVE-2025-36149

6.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
21 November 2025

What is CVE-2025-36149?

IBM Concert Software versions 1.0.0 to 2.0.0 are susceptible to a click hijacking vulnerability that enables remote attackers to manipulate user clicks, potentially leading to unauthorized actions or data exposure. This exploitation could undermine user trust and the overall security posture of affected systems, making it crucial for users to apply necessary security patches and countermeasures.

Affected Version(s)

IBM Concert Software 1.0.0 <= 2.0.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36149 : Remote Attack Vulnerability in IBM Concert Software